← Files Go: Production EngineeringARCHIVED FILE
skills/go-security-hardening/skill.json
4.45 KB · Oct 3, 2026 · 06:33 UTC
{"schema_version":2,"collection":"engineering-skills-for-go","display_name":"Go Security Hardening","short_description":"Trace and close Go trust-boundary paths","default_prompt":"Use $go-security-hardening to threat-model and harden this Go boundary.","version":"0.2.0","maturity":"beta","category":"security","risk_domains":["security","privacy","supply-chain"],"tags":["go","security","authorization","ssrf","cryptography","encryption","key-management","supply-chain","process-execution"],"go_versions":{"minimum":"1.24","guidance":["1.25","1.26"]},"claim_ids":["eng-security-boundary","eng-child-process-boundary"],"relations":{"complements":["go-service-boundaries","go-production-operations"],"overlaps":[]},"compatibility_evidence":[{"client":"codex","level":"behaviorally-benchmarked","contract":"OpenAI skill plus agents/openai.yaml and committed eval artifacts","verified_on":"2026-08-18"},{"client":"claude-code","level":"structurally-compatible","contract":"Claude plugin skill layout and manifest validation","verified_on":"2026-08-18"},{"client":"cursor","level":"structurally-compatible","contract":"Agent Plugin and .cursor/skills layout validation","verified_on":"2026-08-18"},{"client":"opencode","level":"structurally-compatible","contract":".agents/skills layout and portable frontmatter validation","verified_on":"2026-08-18"}],"source_provenance":{"method":"independent-rewrite-from-primary-evidence","reference_repositories":["cc-skills-golang","gophers"],"corpus_lock":"research/corpus-lock.json"},"sources":[{"title":"Go Security Best Practices","url":"https://go.dev/doc/security/best-practices","publisher":"The Go Authors","kind":"primary","verified_on":"2026-08-18","supports":["vulnerability management","fuzzing","dependencies"]},{"title":"NIST Secure Software Development Framework","url":"https://csrc.nist.gov/pubs/sp/800/218/final","publisher":"NIST","kind":"primary","verified_on":"2026-08-18","supports":["secure development","supply chain"]},{"title":"Go Modules Reference","url":"https://go.dev/ref/mod","publisher":"The Go Authors","kind":"primary","verified_on":"2026-08-24","supports":["module authentication","checksum database","private module boundaries"]},{"title":"SLSA Build Track Basics","url":"https://slsa.dev/spec/v1.2/build-track-basics","publisher":"OpenSSF","kind":"primary","verified_on":"2026-08-24","supports":["build provenance","resolved inputs","builder trust"]},{"title":"Package net/http/httputil","url":"https://pkg.go.dev/net/http/httputil","publisher":"The Go Authors","kind":"primary","verified_on":"2026-08-24","supports":["forwarded-header sanitization","reverse proxy rewrite"]},{"title":"RFC 7239 Forwarded HTTP Extension","url":"https://www.rfc-editor.org/rfc/rfc7239","publisher":"IETF","kind":"primary","verified_on":"2026-08-24","supports":["forwarded chain semantics","proxy metadata privacy"]},{"title":"RFC 9440 Client-Cert HTTP Header Field","url":"https://www.rfc-editor.org/rfc/rfc9440","publisher":"IETF","kind":"primary","verified_on":"2026-08-24","supports":["trusted TLS-terminating proxy","client certificate field sanitization"]},{"title":"NIST SP 800-57 Part 1 Rev. 5","url":"https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final","publisher":"NIST","kind":"primary","verified_on":"2026-08-24","supports":["key lifecycle","cryptoperiods","compromise and destruction"]},{"title":"Tink client-side encryption","url":"https://developers.google.com/tink/client-side-encryption","publisher":"Google","kind":"primary","verified_on":"2026-08-24","supports":["DEK and KEK separation","managed envelope encryption"]},{"title":"Tink keysets","url":"https://developers.google.com/tink/design/keysets","publisher":"Google","kind":"primary","verified_on":"2026-08-24","supports":["mixed-key reader rollout","rotation primary cutover"]},{"title":"Package crypto/cipher for Go 1.26","url":"https://pkg.go.dev/crypto/cipher@go1.26.3","publisher":"The Go Authors","kind":"primary","verified_on":"2026-08-24","supports":["AEAD nonce uniqueness","random-nonce GCM usage limit"]},{"title":"Package os/exec for Go 1.26","url":"https://pkg.go.dev/os/exec@go1.26.3","publisher":"The Go Authors","kind":"normative","verified_on":"2026-08-29","supports":["shell-free argument execution","environment and descriptor inheritance","cancellation and WaitDelay","process reaping"]},{"title":"Command PATH security in Go","url":"https://go.dev/blog/path-security","publisher":"The Go Authors","kind":"primary","verified_on":"2026-08-29","supports":["executable path authority","ErrDot security boundary"]}]}
SHA-256: 965f72142a28afabe5eecc54e7bb6573bc77bc0cad0c82d1e21306d5487e7410